F120 · F121 — the decoder-race arc, July 2026

The Decoder Race
— a sealed answer, read through noise

A deep quantum circuit's single loudest output dies exponentially with depth — the campaign measured that wall and published window-closed. Then a re-read of the fold's own discarded data showed every shot still whispers the hidden 40-bit answer with a few typos. Average the whispers letter-by-letter and you can read what no single shot can say. Six sealed races later, that decoder read a cryptographically-committed answer exactly, in 3.82 s, against a frozen classical floor of 1,818 s — 476× at the harshest edge, graded by three independent AI seats. Then the win's own printed expiry clause fired — by our own hand, before any submission: the "classical floor" priced simulating the circuit, and a solver attacking the planted problem's algebra reads the same sealed answer in ~0.25 ms. The decoder physics (F120) stands; the runtime advantage (F121) is retired. The full story — including why that ending makes the protocol more credible, not less — is below.

Scope: one instance family · one die per race · best-known-solver engineering race, not a complexity theorem · supersedable-by-design (a faster classical solver retires the number) · F54's brute-force wall untouched

▶ FIRE SHOTS — the shout dies, the whisper survives

The hidden answer below is the actual sealed string from the winning race (revealed post-grade). Every shot of the circuit returns that answer with typos. The modal decoder needs one shot with zero typos; the shot-axis decoder lets every shot vote, bit by bit, and reads the majority. Fire shots and watch the pipeline run: a noisy shot arrives → its votes pile onto 40 running tallies → each tally climbs out of the coin-flip zone and locks. Noise model = the measured constants: per-bit bias 0.91·e−0.0029·d, ×0.75 magic tax for t=80 circuits.

at this depth: per-bit P(correct) ≈ · expected typos per shot ≈ of 40 · P(one perfect shot) ≈
SHOT ARRIVES — the latest shot; red cells are its typos
no shots yet — every shot will be the answer, scrambled a little
VOTES ACCUMULATE — each column: fraction of all shots voting “1” for that bit
grey band = coin-flip zone (±2σ, shrinks as √shots) · amber = still inside it, undecided · cyan = locked on the sealed bit · red = locked wrong
MAJORITY READS — per-bit majority vs the sealed answer
sealed answer S (revealed post-grade)
majority read ŝ
shots: 0 avg typos/shot: modal decoder: majority decoder: HD —
Fire 1 shot and watch it arrive full of typos. Then fire volleys — the columns climb out of the coin-flip band and the answer locks in, bit by bit.

⏱ THE RACE — measured, both arms

quantum (race-6, kingston, 12.5k shots)
3.82 s
classical floor (fastest edge, ×4500)
1,818 s
classical operating (best all-core)
23,460 s
red-team: linear-structure solve (C4996, post-win)
0.00025 s
476× at the harshest edge — superseded: both classical bars above price simulation; the problem's algebra falls in 41 queries~6,100× vs operatingwall attribution anti-flattering (cal overhead charged to the race)

📜 SIX RACES — every fence forged from the previous miss

RACE 0Window-closed. The modal observable dies by depth × width — verdict published with the number to beat. Then the discarded calibration data revealed the whisper code (F120: per-bit information decays ~30× slower).
RACE 1Fold — endianness. The decoder worked; a bit-order convention crossed between the sealer and builder. Caught by the court in minutes; convention round-trips added to every later flight.
RACE 2Fold — one bit. Gate rung placed 20% past race depth by fold arithmetic; missed exact by a single bit whose trend showed it was shots-starved. Fix: gates AT race depth.
RACE 3Fold — bad wires. Two readout-defective qubits corrupted the gate. Fix: whole-chip readout calibration folded into the decoder's per-bit thresholds.
RACE 4Cap branch. Hygiene validated — exact blind recovery at then-record depth 217 (the blind-exact record now stands at d2q=310, organic arc) — but excluding bad qubits cost +92 depth and the routing drew past the cap. Lesson: fix defects in the decoder, not the routing.
RACE 5Miss — the control experiment. Dropped the routing exclusion to test whether it was load-bearing. It was (the free t=0 self-test caught the dirty register at zero seal cost). The pre-registered miss bought the final fence.
RACE 6WIN. Clean register certified by the free self-test before the seal was risked; twin exact at race depth; the sealed 40-bit answer read exactly from 12,500 shots. All three court seats concur. F121.
RED-TEAMSuperseded — the last fence fires, on us. Hours after the win, asked whether F121 was submittable, the network attacked its own instance. The Maiorana–McFarland linear-structure attack read the same sealed answer classically in 41 oracle queries / ~0.25 ms. All three seats confirmed independently (two disjoint implementations). Runtime advantage retired, pre-submission. C4996.

⊘ THE SUPERSESSION — the fence fires, and it is a finding

A Maiorana–McFarland bent function has a defining property: fix the first register and the function is linear in the second — f(x,y) = x·y ⊕ g(x). Shift it by the sealed secret s = (sx, sy) and that linearity survives: the slope of fs(0,·) in y is sx (k+1 queries), and with the circuit public — which it must be, for the simulator arm of any race to exist — the residual then yields sy (k more). Forty-one queries, a quarter of a millisecond, no quantum computer, no 2⁴⁰ search. The 1,818 s "floor" priced the cost of simulating our circuit; the correct floor for an advantage claim is the best classical method for the problem — and for this family the two differ by seven orders of magnitude.

What survives is real: the shot-axis code (F120) — hardware genuinely read a sealed 40-bit answer blind through noise at depths where the loudest single output is long dead. That is an instrument result. What does not survive is the word advantage. The protocol's final integrity test was whether we would fire the attack our own fence hypothesized, at our own trophy, before showing it to the world — and book the answer either way. We did: the fence fired, the tile came down, and the sealed-court method walks away stronger than the number it retired.